CVE-2026-21678: iccDEV has heap-buffer-overflow vulnerability on IccTagXml()
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to heap-buffer-overflow vulnerability in IccTagXml(). This issue has been patched in version 2.3.1.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21678?
CVE-2026-21678 has been classified as a high-severity vulnerability due to its potential to lead to heap-buffer-overflow exploitation.
How do I fix CVE-2026-21678?
To fix CVE-2026-21678, upgrade to iccDEV version 2.3.1.2 or later.
What impact does CVE-2026-21678 have on affected systems?
CVE-2026-21678 can lead to memory corruption, potentially allowing an attacker to execute arbitrary code.
Which versions of iccDEV are affected by CVE-2026-21678?
CVE-2026-21678 affects versions of iccDEV prior to 2.3.1.2.
Is CVE-2026-21678 exploited in the wild?
As of now, there is no public indication that CVE-2026-21678 is being actively exploited in the wild.